api.telegram.org

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:39

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
149.154.166.110
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Telegram Bot RAT (provisional) 0a40d131965d… C2 2026-08-06
Telegram Bot RAT (provisional) 11d3ca0fb215… C2 2026-08-08
Telegram Bot RAT (provisional) 166fa6d7ea07… C2 2026-08-08
Telegram Bot RAT (provisional) 32a63f043ddb… C2 2026-08-08
Telegram Bot RAT (provisional) 46711079d2af… C2 2026-08-08
SMS Forwarder (provisional) c25f721eba1d… C2 2026-08-17
SMS Forwarder (provisional) 9354d54a1c6b… C2 2026-08-17
Telegram Bot RAT (provisional) ad18c1142247… C2 2026-08-30
Telegram Bot RAT (provisional) 778fcc6a38d4… C2 2026-08-30
SMS Forwarder (provisional) 0050e3ef2812… C2 2026-09-03
SMS Forwarder (provisional) 3dbbc7a01101… C2 2026-09-20
Telegram Bot RAT (provisional) 05cacd5e8417… C2 2026-09-24
Telegram Bot RAT (provisional) 6d2a4e562324… C2 2026-09-24
Telegram Bot RAT (provisional) 7b633b728672… C2 2026-09-29
SMS Forwarder (provisional) a23457417014… C2 2026-09-30
Telegram Bot RAT (provisional) 67765a467b7f… C2 2026-10-03
Telegram Dropper (provisional) e296be45721e… C2 2026-10-05
SMS Forwarder (provisional) e9f1b821f204… C2 2026-10-05
Telegram Bot Stealer (provisional) 7ceb8663fc2c… C2 2026-10-05
Telegram Bot Stealer (provisional) 9ea98d083024… C2 2026-10-08
Telegram Bot RAT (provisional) aa2ffa3854dc… C2 2026-10-09
Telegram Bot RAT (provisional) c515f21565f3… C2 2026-10-09
Telegram Bot RAT (provisional) 066e90d2a3dd… C2 2026-10-09

About SMS Forwarder (provisional)

A broad class of simple **Android OTP/SMS stealers** (packages like `com.example.smsforwarder`) that register a `RECEIVE_SMS` receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only: - **Telegram bot** - the message is sent through the Telegram Bot API; the bot token(s) (`<id>:<authstring>`) and target `chat_id` are hardcoded, so `api.telegram.org` is the C2 and the **bot token is the actionable IOC** (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback). - **HTTP drop** - the message is POSTed to a hardcoded endpoint, typically a bare IP with an `/sms` / `ingest` PHP handler. Family label is provisional - these are commodity builders, not a single actor.

About Telegram Bot RAT (provisional)

**Telegram Bot RAT (provisional)** is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot<token>/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key "UTF-8"). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional.

About Telegram Bot Stealer (provisional)

Android data stealer that exfiltrates to an attacker-run Telegram bot via the Telegram Bot API (api.telegram.org). Seen disguised as a "Free TikTok" app, it ships its bot token, destination chat_id and a decoy redirect as plaintext assets and uses the full Telegram Bot API set (sendMessage/sendDocument/…) to ship stolen SMS and device data to the operator's chat. Family label provisional.

About Telegram Dropper (provisional)

Android banking-malware dropper that leans on commodity cloud services for delivery and control. It pulls second-stage configuration/payloads and exfiltrates data through the Telegram Bot API (api.telegram.org) and t.me channels, with Firebase (Realtime Database / Storage) and DuckDNS hosts (e.g. binarypanel.duckdns.org) used as fallback C2/staging. Family label provisional.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.